CVE-2026-92920

CVE-2026-92920 published: admin3 through 3.0.0 fails to invalidate existing sessions when disabling a user account, allowing attackers to retain authenticated access with original permissions. Attackers can continue using bearer tokens issued before account disablement to authentica...

View full NVD advisory → ← Back to CVE watch